Seeing the Forest and the Trees: A Meta-Analysis of the Antecedents to Information Security Policy Compliance

In stock
A rich stream of research has identified numerous antecedents to employee compliance (and noncompliance) with information security policies. However, the number of competing theoretical perspectives and inconsistencies in the reported findings have hampered efforts to attain a clear understanding of what truly drives this behavior. To address this theoretical stalemate and build toward a consensus on the key antecedents of employees’ security policy compliance in different contexts, we conducted a meta-analysis of the relevant literature. Drawing on 95 empirical papers, we classified 401 independent variables into 17 distinct categories and analyzed each category’s relationship with security policy compliance, including an analysis for possible domain-specific moderators. A meta-analytic relative weight analysis determined the relative importance of each category in predicting security policy compliance, while adding robustness to our findings. At a broad level, our results suggest that much of the security policy compliance literature is plagued by suboptimal theoretical framing. Our findings can facilitate more refined theory-building efforts in this research domain and serve as a guide for practitioners to manage security policy compliance initiatives. 02/25/19
Additional Details
Author W. Alec Cram, John D'Arcy, and Jeffrey G. Proudfoot
Year 2019
Volume 43
Issue 2
Keywords Information security, cybersecurity, information security policies, compliance, meta-analysis, relative weight analysis
Page Numbers 525-554; DOI: 10.25300/MISQ/2019/15117
Copyright © 2023 MISQ. All rights reserved.